APT Iran (MOIS) Active since 2022

UNC1860

Passive backdoor specialist. Provides initial access to other Iranian APTs.

Scroll

UNC1860 is an Iranian MOIS-affiliated threat group that specializes in deploying passive, difficult-to-detect backdoors on internet-facing servers. The group functions as an initial access provider for other Iranian threat actors, deploying HTTPSnoop and PipeSnoop implants that blend with legitimate web server traffic.

AttributeDetail
NamesUNC1860 / ShroudedSnooper
AttributionIran (MOIS)
Active Since2022
Primary FocusPassive backdoor specialist. Provides initial access to other Iranian APTs.

Overview

UNC1860 is an Iranian MOIS-affiliated threat group that specializes in deploying passive, difficult-to-detect backdoors on internet-facing servers. The group functions as an initial access provider for other Iranian threat actors, deploying HTTPSnoop and PipeSnoop implants that blend with legitimate web server traffic.

Attribution

UNC1860 / ShroudedSnooper is attributed to Iran (MOIS), active since at least 2022. Passive backdoor specialist. Provides initial access to other Iranian APTs.

Notable Campaigns

MITRE ATT&CK Mapping

Technique IDTechniqueConfidence
T1190Exploit Public-Facing ApplicationHigh
T1505Server Software ComponentHigh
T1071Application Layer ProtocolHigh
T1059Command and Scripting InterpreterHigh
T1036MasqueradingHigh

Detection & Defense

Recommended Defenses

Monitor for the TTPs listed above using your SIEM and EDR platforms. Prioritize patching of internet-facing applications and enforce MFA on all remote access. Mjolnir Security provides continuous threat hunting and monitoring for UNC1860 activity patterns.

Mjolnir Security — Threat Intelligence & Response

Mjolnir Security provides 24/7 threat monitoring, incident response, and threat intelligence services. Contact us for threat hunting specifically targeting UNC1860 TTPs in your environment.

Threat Hunting Incident Response Threat Intelligence SOC-as-a-Service

mjolnirsecurity.com — 24/7 Incident Response Hotline: +1 833 403 5875